Tk Source Code

View Ticket
Login
2026-06-20
16:43 • Closed ticket [0beaefa4]: Tk_FindPhoto crash plus 7 other changes artifact: 4059ca13 user: jan.nijtmans
11:48
Fix [0beaefa42d]: Tk_FindPhoto crash check-in: 2425cc6d user: jan.nijtmans tags: core-9-0-branch
2026-06-18
19:54 • Add attachment tkImage2.diff to ticket [0beaefa4] artifact: 54d515b6 user: emiliano
19:54 • Ticket [0beaefa4] Tk_FindPhoto crash status still Open with 3 other changes artifact: 8098f26c user: emiliano
18:51 • Add attachment tkImage.diff to ticket [0beaefa4] artifact: 60d94c7a user: emiliano
18:49 • New ticket [0beaefa4] Tk_FindPhoto crash. artifact: 78249ddb user: emiliano

Ticket UUID: 0beaefa42daddbde33cfff6114134e3bdf96d860
Title: Tk_FindPhoto crash
Type: Bug Version: 9.1
Submitter: emiliano Created on: 2026-06-18 18:49:44
Subsystem: 41. Photo Images Assigned To: jan.nijtmans
Priority: 5 Medium Severity: Important
Status: Closed Last Modified: 2026-06-20 16:43:18
Resolution: Fixed Closed By: jan.nijtmans
    Closed on: 2026-06-20 16:43:18
Description:

Calling Tk_FindPhoto() after the main window goes away crashes Tk. The sequence is

  • Tk_FindPhoto() in generic/tkImgPhoto.c calls Tk_GetImageModelData() here.

  • Tk_GetImageModelData() in generic/tkImage.c calls Tk_MainWindow() here. At this point, winPtr is NULL (application destroyed).

  • Right after it calls Tcl_FindHashEntry() here. The program segfaults.

A minimal script to reproduce:

# file crash.tcl
# get extension from https://chiselapp.com/user/egavilan/repository/photorotate
package require photorotate
update
destroy .
photorotate dummy dummy 0.0

Here, photorotate calls Tk_FindPhoto() on their two first arguments. Running it

$ make shell SCRIPT=crash.tcl 
make: *** [Makefile:254: shell] Segmentation fault (core dumped)

The solution is to return NULL if winPtr is NULL. Patch is attached.

User Comments: jan.nijtmans added on 2026-06-20 16:43:18:

Fixed now in 9.0 branch and trunk


emiliano added on 2026-06-18 19:54:00:
Spoke too soon. Not only the function has to return NULL, but also it has to set *typePtrPtr to NULL as well.

New patch attached.

Attachments: